RE: Linux hardening

<[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <93AF242CD7F2A14A91CA742C490AC3BEAD0A58@tshuscodenmbx02.ERF.THOMSON.COM>

You can try to install APF (Firewall) and BFD (Brute Force Detection)
and also follow some of the steps outlined here:

http://www.webhostingresourcekit.com/109.html 

APF and BFD are made by rfxnetworks.com. BFD will automatically block
attackers if they fail to authenticate 5 times by using APF.

Christoph

-----Original Message-----
From: AragonX [mailto:[email protected]]
Sent: Sunday, August 21, 2005 6:14 AM
To: [email protected]
Subject: Linux hardening

I had an intrusion on one of my servers and am in the process of
hardening it (after a reinstall).  I'm using Fedora Core 4.  I've taken
all the basic steps (shutting down unused services etc) and have done
the
following:

Installed Smothwall on a separate box.
Installed & configured AIDE, Snort and chkrootkit Ran Bastille

I am in the process of configuring LIDS.  I'm using LIDS instead of
SELinux because it's easier for me to configure.

My next and final step will be to install mod_security.

The server performs the following tasks:

   Web (Squirrelmail, eGroupWare, myPhpAdmin and others) and email
serving to the internet.
   File, print and DHCP serving to my local network.

I'm looking for more preventative measures.  It appears that LIDS and
mod_security are the only ones in that role now.  Should I jail apache?
Would that give me any benefits over what LIDS provides?

Thank you in advance.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.